{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,10]],"date-time":"2024-09-10T21:38:23Z","timestamp":1726004303579},"publisher-location":"Cham","reference-count":41,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030017033"},{"type":"electronic","value":"9783030017040"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-01704-0_17","type":"book-chapter","created":{"date-parts":[[2018,12,28]],"date-time":"2018-12-28T16:02:50Z","timestamp":1546012970000},"page":"311-331","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["FrameHanger: Evaluating and Classifying Iframe Injection at Large Scale"],"prefix":"10.1007","author":[{"given":"Ke","family":"Tian","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhou","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kevin D.","family":"Bowers","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Danfeng","family":"Yao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,12,29]]},"reference":[{"key":"17_CR1","unstructured":"The easylist filter lists. https:\/\/easylist.to\/ . Accessed 10 Oct 2017"},{"key":"17_CR2","unstructured":"The easyprivacy filter lists. https:\/\/easylist.to\/easylist\/easyprivacy.txt . Accessed 10 Oct 2017"},{"key":"17_CR3","unstructured":"Framehanger released version. https:\/\/github.com\/ririhedou\/FrameHanger"},{"key":"17_CR4","unstructured":"Google tag manager quick start. https:\/\/developers.google.com\/tag-manager\/quickstart . Accessed 10 Oct 2017"},{"key":"17_CR5","unstructured":"A javascript minifier written in python. https:\/\/github.com\/rspivak\/slimit . Accessed 10 Oct 2017"},{"key":"17_CR6","unstructured":"Malvertising campaigns involving exploit kits. https:\/\/www.fireeye.com\/blog\/threat-research\/2017\/03\/still_getting_served.html . Accessed 10 Oct 2017"},{"key":"17_CR7","unstructured":"Obfuscation service. https:\/\/javascriptobfuscator.com\/ . Accessed 10 Oct 2017"},{"key":"17_CR8","unstructured":"RSA shadow fall. https:\/\/www.rsa.com\/en-us\/blog\/2017-06\/shadowfall . Accessed 10 Oct 2017"},{"key":"17_CR9","unstructured":"Same original policy. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Security\/Same-origin_policy . Accessed 10 Oct 2017"},{"key":"17_CR10","unstructured":"Scrapy cralwer framework. https:\/\/scrapy.org\/ . Accessed 10 Oct 2017"},{"key":"17_CR11","unstructured":"Selenium automates browsers. http:\/\/www.seleniumhq.org\/"},{"key":"17_CR12","unstructured":"Tree-based importance score. http:\/\/scikit-learn.org\/stable\/auto_examples\/ensemble\/plot_forest_importances.html . Accessed 10 Oct 2017"},{"key":"17_CR13","unstructured":"X-frame-options or CSP frame-ancestors? https:\/\/oxdef.info\/csp-frame-ancestors\/ . Accessed 10 Oct 2017"},{"key":"17_CR14","doi-asserted-by":"crossref","unstructured":"Argyros, G., Stais, I., Jana, S., Keromytis, A.D., Kiayias, A.: SFADiff: automated evasion attacks and fingerprinting using black-box differential automata learning. In: Proceedings of CCS (2016)","DOI":"10.1145\/2976749.2978383"},{"key":"17_CR15","doi-asserted-by":"crossref","unstructured":"Blum, A., Wardman, B., Solorio, T., Warner, G.: Lexical feature based phishing URL detection using online learning. In: Proceedings of AISec (2010)","DOI":"10.1145\/1866423.1866434"},{"key":"17_CR16","doi-asserted-by":"crossref","unstructured":"Borgolte, K., Kruegel, C., Vigna, G.: Delta: automatic identification of unknown web-based infection campaigns. In: Proceedings of CCS (2013)","DOI":"10.1145\/2508859.2516725"},{"key":"17_CR17","doi-asserted-by":"crossref","unstructured":"Calzavara, S., Rabitti, A., Bugliesi, M.: Content security problems?: evaluating the effectiveness of content security policy in the wild. In: Proceedings of CCS (2016)","DOI":"10.1145\/2976749.2978338"},{"key":"17_CR18","doi-asserted-by":"crossref","unstructured":"Canali, D., Cova, M., Vigna, G., Kruegel, C.: Prophiler: a fast filter for the large-scale detection of malicious web pages. In: Proceedings of WWW (2011)","DOI":"10.1145\/1963405.1963436"},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Catakoglu, O., Balduzzi, M., Balzarotti, D.: Automatic extraction of indicators of compromise for web applications. In: Proceedings of WWW (2016)","DOI":"10.1145\/2872427.2883056"},{"key":"17_CR20","unstructured":"Choi, H., Zhu, B.B., Lee, H.: Detecting malicious web links and identifying their attack types. In: Proceedings of USENIX Conference on Web Application Development (2011)"},{"key":"17_CR21","doi-asserted-by":"crossref","unstructured":"Cova, M., Kruegel, C., Vigna, G.: Detection and analysis of drive-by-download attacks and malicious JavaScript code. In: Proceedings of WWW (2010)","DOI":"10.1145\/1772690.1772720"},{"key":"17_CR22","unstructured":"Curtsinger, C., Livshits, B., Zorn, B.G., Seifert, C.: ZOZZLE: fast and precise in-browser JavaScript malware detection. In: Proceedings of USENIX Security (2011)"},{"key":"17_CR23","doi-asserted-by":"crossref","unstructured":"Englehardt, S., Narayanan, A.: Online tracking: a 1-million-site measurement and analysis. In: Proceedings of CCS (2016)","DOI":"10.1145\/2976749.2978313"},{"key":"17_CR24","doi-asserted-by":"crossref","unstructured":"Hu, X., Cheng, Y., Duan, Y., Henderson, A., Yin, H.: JSForce: a forced execution engine for malicious JavaScript detection. CoRR, abs\/1701.07860 (2017)","DOI":"10.1007\/978-3-319-78813-5_37"},{"key":"17_CR25","unstructured":"Kaplan, S., Livshits, B., Zorn, B., Seifert, C., Curtsinger, C.: \"NOFUS: Automatically Detecting\"+ String. fromCharCode (32)+ \"ObFuSCateD \".toLowerCase()+ \"JavaScript Code\". Technical report MSR-TR-2011-57, Microsoft Research, May 2011"},{"key":"17_CR26","doi-asserted-by":"crossref","unstructured":"Kim, K., et al.: J-force: forced execution on JavaScript. In: Proceedings of WWW (2017)","DOI":"10.1145\/3038912.3052674"},{"key":"17_CR27","doi-asserted-by":"crossref","unstructured":"Kolbitsch, C., Livshits, B., Zorn, B., Seifert, C.: Rozzle: de-cloaking internet malware. In: Proceedings of Security and Privacy (Oakland) (2012)","DOI":"10.1109\/SP.2012.48"},{"key":"17_CR28","doi-asserted-by":"crossref","unstructured":"Kumar, D., et al.: Security challenges in an increasingly tangled web. In: Proceedings of WWW (2017)","DOI":"10.1145\/3038912.3052686"},{"key":"17_CR29","doi-asserted-by":"crossref","unstructured":"Lauinger, T., Chaabane, A., Arshad, S., Robertson, W., Wilson, C., Kirda, E.: Thou shalt not depend on me: analysing the use of outdated JavaScript libraries on the web. In: Proceedings of NDSS (2017)","DOI":"10.14722\/ndss.2017.23414"},{"key":"17_CR30","doi-asserted-by":"crossref","unstructured":"Le, A., Markopoulou, A., Faloutsos, M.: PhishDef: URL names say it all. In: Proceedings of INFOCOM (2011)","DOI":"10.1109\/INFCOM.2011.5934995"},{"key":"17_CR31","doi-asserted-by":"crossref","unstructured":"Li, Z., Alrwais, S. Wang, X., Alowaisheq, E.: Hunting the red fox online: Understanding and detection of mass redirect-script injections. In: Proceedings of Security and Privacy (Okaland) (2014)","DOI":"10.1109\/SP.2014.8"},{"issue":"3","key":"17_CR32","first-page":"30","volume":"2","author":"J Ma","year":"2011","unstructured":"Ma, J., Saul, L.K., Savage, S., Voelker, G.M.: Learning to detect malicious URLs. ACM Trans. Intell. Syst. Technol. (TIST) 2(3), 30 (2011)","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"key":"17_CR33","doi-asserted-by":"crossref","unstructured":"Nikiforakis, N., et al.: You are what you include: large-scale evaluation of remote JavaScript inclusions. In: Proceedings of CCS (2012)","DOI":"10.1145\/2382196.2382274"},{"key":"17_CR34","unstructured":"Provos, N., Panayiotis, M., Rajab, M.A., Monrose, F.: All your iFRAMEs point to us. In: Proceedings of USENIX Security (2008)"},{"key":"17_CR35","doi-asserted-by":"crossref","unstructured":"Saxena, P., Akhawe, D., Hanna, S., Mao, F., McCamant, S., Song, D.: A symbolic execution framework for JavaScript. In: Proceedings of Security and Privacy (Okaland) (2010)","DOI":"10.1109\/SP.2010.38"},{"key":"17_CR36","doi-asserted-by":"crossref","unstructured":"Sen, K., Kalasapur, S., Brutch, T., Gibbs, S.: Jalangi: a selective record-replay and dynamic analysis framework for JavaScript. In: Proceedings of ESEC\/FSE (2013)","DOI":"10.1145\/2491411.2491447"},{"key":"17_CR37","unstructured":"Soska, K., Christin, N.: Automatically detecting vulnerable websites before they turn malicious. In: Proceedings of USENIX Security (2014)"},{"key":"17_CR38","doi-asserted-by":"crossref","unstructured":"Stock, B., Livshits, B., Zorn, B.: KIZZLE: a signature compiler for exploit kits. In International Conference on Dependable Systems and Networks (DSN), June 2016","DOI":"10.1109\/DSN.2016.48"},{"key":"17_CR39","doi-asserted-by":"crossref","unstructured":"Weichselbaum, L., Spagnuolo, M., Lekies, S., Janc, A.: CSP is dead, long live CSP! on the insecurity of whitelists and the future of content security policy. In: Proceedings of CCS (2016)","DOI":"10.1145\/2976749.2978363"},{"key":"17_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1007\/978-3-319-11379-1_11","volume-title":"Research in Attacks, Intrusions and Defenses","author":"M Weissbacher","year":"2014","unstructured":"Weissbacher, M., Lauinger, T., Robertson, W.: Why is CSP failing? Trends and challenges in CSP adoption. In: Stavrou, A., Bos, H., Portokalidis, G. (eds.) RAID 2014. LNCS, vol. 8688, pp. 212\u2013233. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11379-1_11"},{"key":"17_CR41","doi-asserted-by":"crossref","unstructured":"Xu, W., Zhang, F. Zhu, S.: Jstill: mostly static detection of obfuscated malicious JavaScript code. In: Proceedings of AsiaCCS (2013)","DOI":"10.1145\/2435349.2435364"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-01704-0_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,9]],"date-time":"2022-09-09T06:23:28Z","timestamp":1662704608000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-01704-0_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030017033","9783030017040"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-01704-0_17","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 August 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 August 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/securecomm.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}